Browse vulnerabilities
379,813 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69586 | Medium | 1.0% | 9.8 | Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to… | |
| CVE-2026-69590 | Medium | 1.0% | 9.8 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker … | |
| CVE-2026-69595 | Medium | 1.0% | 9.8 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attack… | |
| CVE-2026-69715 | Medium | 1.0% | 9.8 | Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code … | |
| CVE-2026-69730 | Medium | 1.0% | 9.8 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a netwo… | |
| CVE-2026-69768 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute cod… | |
| CVE-2026-69769 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker … | |
| CVE-2026-69819 | Medium | 1.0% | 9.8 | Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a … | |
| CVE-2026-69824 | Medium | 1.0% | 9.8 | Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized at… | |
| CVE-2026-69829 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute cod… | |
| CVE-2026-69910 | Medium | 1.0% | 9.8 | Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute … | |
| CVE-2026-70296 | Medium | 1.0% | 9.8 | Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execut… | |
| CVE-2026-72979 | Medium | 1.0% | 9.8 | Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over… | |
| CVE-2026-72982 | Medium | 1.0% | 9.8 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute… | |
| CVE-2026-72983 | Medium | 1.0% | 9.8 | Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacke… | |
| CVE-2026-73009 | Medium | 1.0% | 9.8 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized a… | |
| CVE-2026-73010 | Medium | 1.0% | 9.8 | Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code… | |
| CVE-2026-77493 | Medium | 1.0% | 9.8 | Double free in Microsoft Graphics Component allows an unauthorized attacker to execute cod… | |
| CVE-2026-78445 | Medium | 1.0% | 9.8 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attack… | |
| CVE-2026-78509 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to … | |
| CVE-2026-78510 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute … | |
| CVE-2026-8476 | Medium | 1.0% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerabili… | |
| CVE-2024-26592 | Medium | 1.0% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue … | |
| CVE-2026-32285 | Medium | 1.0% | 7.5 | The Delete function fails to properly validate offsets when processing malformed JSON inpu… | |
| CVE-2026-50006 | Medium | 1.0% | 9.1 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server fo… | |
| CVE-2026-62835 | Medium | 1.0% | 9.3 | Improper authorization in Azure Portal allows an unauthorized attacker to disclose informa… | |
| CVE-2026-66304 | Medium | 1.0% | 7.5 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker t… | |
| CVE-2026-66800 | Medium | 1.0% | 8.6 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker t… | |
| CVE-2026-68502 | Medium | 1.0% | 9.8 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior… | |
| CVE-2026-69558 | Medium | 1.0% | 8.6 | Authorization bypass through user-controlled key in Microsoft Partner Center allows an una… | |
| CVE-2026-9076 | Medium | 1.0% | 7.5 | Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes a… | |
| CVE-2020-1010 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Servic… | |
| CVE-2020-1135 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists when the Windows Graphics Component imprope… | |
| CVE-2026-30310 | Medium | 1.0% | 9.8 | In its design for automatic terminal command execution, Sixth offers two options: Execute … | |
| CVE-2026-48326 | Medium | 1.0% | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2026-57131 | Medium | 1.0% | 9.8 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app… | |
| CVE-2026-71981 | Medium | 1.0% | 8.8 | Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticate… | |
| CVE-2026-7465 | Medium | 1.0% | 8.8 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress i… | |
| CVE-2026-82010 | Medium | 1.0% | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements… | |
| CVE-2026-14913 | Medium | 1.0% | 8.8 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vul… | |
| CVE-2026-47698 | Medium | 1.0% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup… | |
| CVE-2026-56671 | Medium | 1.0% | 7.5 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Pr… | |
| CVE-2026-63913 | Medium | 1.0% | 8.2 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack:… | |
| CVE-2026-14512 | Medium | 1.0% | 9.8 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authenticat… | |
| CVE-2026-44168 | Medium | 1.0% | 8.0 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to befo… | |
| CVE-2020-3317 | Medium | 1.0% | 7.5 | A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) So… | |
| CVE-2023-21778 | Medium | 1.0% | 8.0 | Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | |
| CVE-2026-26278 | Medium | 1.0% | 7.5 | fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS… | |
| CVE-2026-56681 | Medium | 1.0% | 7.3 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requ… | |
| CVE-2026-53977 | Medium | 1.0% | 7.5 | OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthentic… |